May 15, 2007

Tech groups support new cybersecurity bill

legislation would broaden penalties for cybercrime including botnet attacks

A tech trade group and a leading cybersecurity vendor applauded new legislation introduced in the U.S. Congress that would broaden penalties for cybercrime, including first-time penalties for botnet attacks.

The Cyber Security Enhancement Act, introduced Monday, would create for the first time criminal penalties for botnet attacks often used to aid identity theft, denial-of-service attacks, and the spread of spam and spyware. Botnets are groups of compromised computers that hackers can control remotely.

The bill, introduced by Representatives Adam Schiff, a California Democrat, and Steve Chabot, an Ohio Republican, would also allow prosecutors to pursue racketeering charges against cybercriminal groups, would expand sentencing guidelines for cybercrime by allowing the forfeiture of property used to commit the crime, and would add $30 million a year to the budgets of federal agencies fighting cybercrime.

The Business Software Alliance (BSA), a trade group, and Symantec, a security vendor, both offered support for the legislation. BSA and other tech trade groups have pushed Congress to pass tougher cybersecurity legislation, and BSA said its member company CEOs will push for passage of the bill when they meet in Washington, D.C., in June.

"For too long. cyber criminals have taken advantage of legal blind spots and an under-resourced law enforcement community to brazenly threaten online confidence and security," BSA President and CEO Robert Holleyman said in a statement. "This legislation will give law enforcement updated and improved tools to combat what has become a growing, organized criminal enterprise."

Symantec, in a statement, cheered the cosponsors effort to target botnets. The sophistication of cybercrimes, particularly botnets, "far outstrips the laws on the books," said John Thompson, the company's chairman and CEO. The bill shows Congress is "truly serious" about combating cybercrime, he added.

The bill would also broaden the definition of electronic data theft related to interstate or foreign communication, and expand the cyber extortion statute.

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

The one-stop resource center for IT professionals.

White Paper

CA Security Management Solutions

A comprehensive security management solution can help you streamline, as well as grow, your current or evolving business. In this way, a strategic security approach can help you increase your competitiveness in these challenging market conditions.

Download now! »

White paper

Beyond Compliance: The Significant Benefits of Log Management

Find out how you can effectively collect, normalize and archive enterprise-wide, security-related data that is invaluable for security investigation and compliance reporting.

Download now! »

Webcast

Integrated Identity Compliance: Enabling Cost-Effective Role-Based Compliance

This session focuses on the intersection of role management and identity compliance, and addresses the importance of identity compliance in enterprise governance and the challenges that organizations may face in achieving it.

View now! »
©1994-2009 Infoworld, Inc.